Tactic or Technique: Exploit

Exploit-based attacks take advantage of software vulnerabilities to compromise your system, often without you needing to click a link or enter credentials. Instead of stealing passwords, attackers use specially crafted files that run malicious code when you open or preview an attachment.
You might see a booby-trapped Office document, PDF, or media file that targets a flaw in your browser or document viewer. Once the file is opened, the attacker can install malware, steal data, or get long-term access to your device without any obvious signs.
These attacks are dangerous because they don’t rely on tricking you with a fake login or link. A file might look completely normal, but opening it is enough. Exploits like this are often used as the first step in ransomware attacks, data theft, or more targeted intrusions.
The best defense is keeping your software up to date. Most of these attacks rely on known vulnerabilities that already have fixes available, as long as you've applied them.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ZIP file with CVE-2026-0866 exploit
10d ago
Mar 20th, 2026
Sublime Security
Attachment: Archive containing HTML file with file scheme link
13d ago
Mar 17th, 2026
Sublime Security
Anthropic Magic String in HTML
1mo ago
Feb 9th, 2026
Sublime Security
Callback phishing via SignFree e-signature request
2mo ago
Jan 12th, 2026
Sublime Security
CVE-2023-5631 - Roundcube Webmail XSS via crafted SVG
2mo ago
Jan 12th, 2026
Sublime Security
Callback phishing via Xodo Sign comment
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: CVE-2023-21716 - Microsoft Office Remote Code Execution Vulnerability
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: LNK with embedded content
2mo ago
Jan 12th, 2026
@ajpc500
Attachment: WinRAR CVE-2025-8088 exploitation
2mo ago
Jan 12th, 2026
Sublime Security
Callback Phishing via Signable E-Signature Request
2mo ago
Jan 12th, 2026
Sublime Security
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
3mo ago
Dec 10th, 2025
Sublime Security
Mass campaign: Cross Site Scripting (XSS) attempt
8mo ago
Jul 16th, 2025
Sublime Security
Open redirect: City of Calgary
10mo ago
May 23rd, 2025
Sublime Security
Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
1y ago
Mar 21st, 2025
Sublime Security
Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
2y ago
Feb 15th, 2024
Sublime Security
Attachment: Archive contains DLL-loading macro
3y ago
Dec 28th, 2023
Sublime Security